CORECORE

Hardened, monitored, and .

Most attacks on business sites are automated — bots probing for known weak points. We close those doors, watch the pieces that matter, and keep a restore plan on the shelf so a bad day stays a short one.

Site Security & Protection — product preview

Recommended stack

What we typically protect it with

Most sites we secure run behind Cloudflare at the edge, on managed hosting like Vercel, with Postgres and row-level security underneath — plus GitHub-based checks that catch bad changes before they ship. That's our recommended setup, not a requirement; we harden and monitor what you already run.

CloudflareCloudflareCDN & security
VercelVercelHosting & cloud
SupabaseSupabaseBackend & APIs
Next.jsNext.jsWeb framework
GitHubGitHubSource & CI/CD
PostgreSQLPostgreSQLDatabase & storage
RedisRedisDatabase & storage
Node.jsNode.jsBackend & APIs
TypeScriptTypeScriptLanguage & tooling
AWSAWSHosting & cloud
CloudflareCloudflareCDN & security
VercelVercelHosting & cloud
SupabaseSupabaseBackend & APIs
Next.jsNext.jsWeb framework
GitHubGitHubSource & CI/CD
PostgreSQLPostgreSQLDatabase & storage
RedisRedisDatabase & storage
Node.jsNode.jsBackend & APIs
TypeScriptTypeScriptLanguage & tooling
AWSAWSHosting & cloud

Every tool above is proven in production across our builds — recommended, not required. See everything we deliver

Managed protection layer

Security operations for sites that can't afford to look careless.

We combine practical hardening, edge protection, uptime checks, malware scanning, and clear reporting into one managed layer.

24/7

uptime watch

WAF

edge rules

1

monthly report

01

Edge firewall

Block bad traffic before it reaches your app.

Managed WAF rules, rate limits, IP reputation, and exploit filters catch common attacks at the edge instead of letting every request touch your origin.

02

Abuse controls

Keep forms, analytics, and checkout usable.

Bot filtering, form spam controls, and escalation rules reduce junk submissions without making real customers fight the site.

03

Recovery path

Know what gets restored and who owns it.

Backup coverage, restore procedures, and incident notes are documented so a bad deploy, outage, or compromise has a clear response path.

Monthly security brief

Plain-English reporting, not mystery dashboards.

  • Blocked requests and bot trends
  • Uptime, SSL, and response checks
  • Patch notes and dependency watchlist
  • Remediation notes when something changes

Incident path

DetectContainRecover

Your agent coordinates response, documents what changed, and keeps recovery actions tied to the site stack.

Lower-cost visibility

Monitoring & Troubleshooting

Essentials

$9/mo

Error tracking, performance traces, logs, uptime checks, and release diagnostics for teams that need technical evidence without the full security layer.

  • 1 managed user and unlimited monitored projects
  • 5,000 errors, 5 GB logs, and 5 GB application metrics per month
  • 5,000,000 tracing spans and 50 privacy-masked session replays per month
  • 1 uptime monitor, 1 cron monitor, and up to 20 metric monitors
Add monitoring to estimate

Complete protection

Site Protection

Monitoring included

$25/mo

Firewall, DNS management, bot filtering, uptime watch, malware hardening, and the complete monitoring tier included at no extra charge.

  • Web application firewall
  • DNS records, routing & domain verification managed for you
  • Bot & spam filtering
  • 24/7 uptime monitoring & alerts
  • Malware scanning & hardening
Add protection to estimate

Works with your current stack

Modern managed hosting, content sites, custom applications, domains, DNS, and supported legacy platforms can all be reviewed and protected.

Care plan friendly

Maintenance keeps the site healthy. Protection watches the public edge, abuse patterns, uptime, errors, and recovery posture.

Pricing, in plain terms

One managed protection layer — priced by scope

Hardening, monitoring, and backups run as an ongoing protection layer under your care plan. A one-time audit and any cleanup are quoted first; you approve the number before we start.

A preview, not a final bill

Prices shown are estimates for a typical build at this tier. You approve a fixed, written quote before any work begins — no surprise charges later.

What's billed separately

Tax, usage-based fees (voice minutes, AI messages, ad spend), hosting, and monthly care plans are separate from the one-time build price.

Estimate → quote → build

Build your estimate online, we review the scope and send a fixed quote, you approve, then we build. You always see the number before you commit.

DisclaimerExcludes tax, usage fees, hosting, and monthly revisions / care plans.

Common questions

  • No — it's practical hardening and monitoring for business sites. We close the doors automated attacks actually use. If you need a formal penetration test or a compliance audit, we scope that as a separate engagement.